CVE-2016-8492 describes a vulnerability in Fortinet FortiGate devices, specifically within their implementation of the ANSI X9.31 Random Number Generator. This flaw allows attackers to achieve unauthorized read access to data, particularly through IPSec/TLS decryption. Rated as MEDIUM severity with a CVSS score of 5.9, it is a network-based attack with high complexity, potentially leading to significant confidentiality impact. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential implications.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.3.18CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
4.3.0CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:4.3.0:*:*:*:*:*:*:* | ||
4.3.10CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:4.3.10:*:*:*:*:*:*:* | ||
4.3.12CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:4.3.12:*:*:*:*:*:*:* | ||
4.3.13CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:4.3.13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.